跳到正文
原文
Together AI 研究与产品博客(RSS)·· 2026-04-30AI 评分61

Together AI 复盘处置 Linux 内核漏洞 Copy Fail(CVE-2026-31431)的生产应急响应

From 732 bytes to nowhere: shutting down Copy Fail in production

AI 导读

Together AI 在生产环境中处置了 Linux 内核 crypto 子系统漏洞 Copy Fail(CVE-2026-31431),该漏洞位于 algif_aead AF_ALG 接口,允许任意非特权本地用户向系统上任意可读文件的 page cache 做精确 4 字节写入,且不改变磁盘文件、不标记脏页,可绕过传统文件完整性检查并借此提权到 root。

来源:Together AI 研究与产品博客(RSS) · together.ai